2018-08-08 UTC
# ↩️ Without the secret, there is no authentication of the client. PKCE solves this by using essentially an on-the-fly secret safe for use by mobile apps. IndieAuth *could* adopt the PKCE extension as well, tho afaik noone has done that yet. ( twitter.com/_/status/1027184371072004097)